Hello there!

Need Help? We are right here!

miniOrange Support Chat - Get Help and Support
miniOrange Email Support
Success Checkmark - Form Submitted Successfully

Thanks for your Enquiry.

If you don't hear from us within 24 hours, please feel free to send a follow-up email to uemsupport@xecurify.com

Search Results:

×

How to Enroll Android Devices into Mobile Device Management (MDM)


Mobile Device Management (MDM) enables organizations to securely enroll, manage, and control Android devices from a central platform. This step-by-step guide explains how to set up miniOrange Mobile Device Management (MDM) for Android devices and apply essential device policy restrictionsto ensure security and compliance.
To learn more about MDM, visit the miniOrange Android Mobile Device Management (MDM) Solution page.


Follow the Step-by-Step Guide given below for Enroll Android Devices for MDM

Step 1: Sign in with miniOrange

Step 2: Setup Android Enterprise Registration

  • Once logged in, navigate to Getting Started → Android and click the Enterprise Registration button. You will need to register your organization with Android Enterprise, which is a one-time setup process.
  • Android Enterprise registration in miniOrange UEM for Android MDM and corporate device enrollment

  • A new window will open, taking you to the Google Enterprise registration page.
  • Choose the email type you want to use for Android Enterprise registration:


    • Enter the personal email address you'd like to link to your Android Enterprise account, then click Next.
    • Enter personal email to create an Android Enterprise account for Android MDM enrollment and Managed Google Play

    • Now, you will be redirected to the next page where you need to click on Sign Up.
    • Sign Up button for Android Enterprise MDM registration and Google Play Admin onboarding

    • On the Google Play Admin sign-up page, click the Get Started button to continue with the setup.
      Google Play Admin Get Started screen for Android Enterprise setup and Android MDM enrollment

    • Enter your Domain Name or Business Name as per your choice.
    • Enter organization domain or business name for Android Enterprise MDM and company-owned device management

    • In the Contact Details section, providing information is optional — you can either skip this step or fill in your contact details.
    • Once done, check the box to confirm the accuracy of the information provided, then click the Confirm button to proceed.
    • Android Enterprise contact details and confirm step before completing Android MDM enrollment registration

    • Now, click on Complete Registration button to complete the process of Android Enterprise registration.
    • Complete Registration to finish Android Enterprise binding for Android MDM and Work Profile management

  • You’ll be redirected back to the miniOrange UEM dashboard, where your enterprise details will be displayed.
  • Android Enterprise registration successful with enterprise details shown for Android MDM in miniOrange UEM

Step 3: Configure Device Policies

  • Go to Device Policies -> Android –> Policies and click on Create Policy to create the policy.
  • Create Android device policy for Android Enterprise MDM security controls and compliance

  • Enter a name and description for your policy. You can then configure different policy settings such as App Settings, Password Settings, Security, etc.
  • Once done, click on Next button.
  • Android MDM policy wizard with name description and app settings for Android Enterprise device management

  • In App Catalog, click on App Configuration → Add Apps to add all the work apps that you want to be installed on the enrolled devices.
  • Managed Google Play App Catalog in Android MDM policy for Android Enterprise work apps

  • A pop-up will open the Google Managed Play Store, where you can search for the required application. After selecting the app, click the Select button to add it to your policy configuration. Close the popup.
  • Select Managed Google Play work apps for Android Enterprise MDM policy and BYOD enrollment

  • Once you close the Play Store, you can see the list of all selected applications. You can set the installation type of apps on this screen.
  • Android MDM policy app list with installation types for Android Enterprise mobile application management

  • For each added app, you can configure extended settings. If the app supports managed configurations, click the three-dot menu next to the app and select Manage Configurations to apply the required settings.
  • Manage Configurations menu for Android Enterprise work apps in Android MDM policy

    Managed app configuration settings for Android Enterprise MDM and secure work app deployment

  • Clicking on Runtime Permission for any app will open the following configuration that specifies the runtime permissions requested that are specific to each app.
  • Runtime permissions for Android apps in Android MDM policy for Android Enterprise security

    Configure runtime permissions for Android MDM managed apps on Android Enterprise devices

  • Clicking on Advanced Settings will open the following configurations that include settings such as Update Mode, Patch Management, Widgets, etc.
  • Advanced Settings for Android app configuration in Android Enterprise MDM policy

    Advanced Android MDM settings including update mode patch management and widgets for Android Enterprise

  • In Password Settings, you can set the password for Work Profile and specify the password quality, password history, etc.
  • Password policy settings for Android Work Profile and Android Enterprise MDM compliance

  • There are Device functionality settings such as configuring the Camera permissions, Screen recording permissions, etc.
  • Android MDM device restrictions for camera and screen recording on Android Enterprise managed devices

  • Data sharing settings provide configurations for cross-profile data sharing such as copy-paste, Data access, etc.
  • Cross-profile data sharing controls for Android Work Profile and Android Enterprise MDM security

  • In the Kiosk tab, you can configure Single App or Multi App mode to restrict the device to specific applications.
  • In single-app kiosk mode, set the app's installation type to Kiosk to display the apps added for kiosk use.
  • Android kiosk mode for single-app and multi-app lockdown with Android Enterprise MDM

  • In the Security Settings, you can set Compliance Rules for actions like Factory Reset, Developer Settings, and other security requirements for Work Profiles.
  • Android MDM security compliance rules for factory reset and developer options on Android Enterprise devices

  • In the OS Patch Management, you can set the System Update Priority, choosing from options like Automatic, Postponed, or Windowed updates to manage when and how updates are applied.
  • OS patch management and system update priority for Android MDM and Android Enterprise patch compliance

  • In the Network Settings, you can configure VPN, WiFi, and Proxy settings to ensure secure and optimized network connectivity for devices.
  • Android MDM network policy for VPN WiFi and proxy on Android Enterprise managed devices

  • Once you have configured all details, click on Submit and your new policy will be listed as shown in the image below.
  • New Android MDM policy listed in miniOrange UEM for Android Enterprise device enrollment

Step 4: Create Device Groups

  • Now, we will create a device group to apply the configured policies to the devices. To do this, go to Manage Devices → Device Groups → Android and click the Add Device Group button.
  • Add Android device group for Android Enterprise MDM policy assignment and bulk enrollment

  • A form will appear prompting you to enter a name for the new device group, assign a policy, and optionally add a description to provide more context about the group.
  • Once done, click on Next button.
  • Android MDM device group form with policy assignment for Android Enterprise enrollment groups

  • If you want to assign the devices to the new device group, select them from the Associated Devices list.
  • If you don’t have any existing devices, just click Add to continue.
  • Associate enrolled Android devices with an Android Enterprise MDM device group

  • The device group has now been successfully created.
  • Android device group created successfully for Android MDM and Android Enterprise policy rollout

Step 5: Create Users

  • Now, Go to the Manage Users -> Email Users tab and click on Add User to create a new user.
  • Add user for Android MDM enrollment and Android Enterprise device assignment in UEM

  • A form will appear prompting you to enter the first name, last name, email, and username. After filling in the required details, click Add to create the user.
  • Create MDM user with email and username for Android Enterprise enrollment invitations

  • Bulk Import Users
    • For adding multiple users at once, click on the Bulk Upload button.
    • Bulk upload users with CSV for Android MDM and faster Android Enterprise device enrollment

    • Prepare a CSV file with “Email” and “Username” columns. (Click Download Sample File for the correct format.) Then, upload the CSV using the Choose File option and click Upload.
    • Upload CSV of users for Android Enterprise MDM bulk enrollment and mobile device management

  • You can now see that the user has been created successfully.
  • User created successfully for Android MDM enrollment and Android Enterprise Work Profile setup

Step 6: Device Enrollment

  • To enroll devices, go to Manage Devices → Devices → Android and click Enroll Android Devices. You can also use the Bulk Device Enrollment button to enroll multiple devices at once.
  • Enroll Android devices into Android Enterprise MDM from miniOrange UEM device management console

  • Select the user from the dropdown which you want to send email and Choose device type "Personal" or "Corporate".
  • Assign the device to a group from group dropdown.
  • Choose enrollment type "By User Invite" or "By Myself".
    • By User Invite - Send an email with a QR code and an enrollment token with necessary steps to enroll the device.
    • By Myself (IT Admin) - IT admin can enroll the device by himself/herself. Details are shown on the screen along with the steps to enroll.
  • Click the Send Enrollment Email button.
  • Android MDM enrollment form for personal or corporate devices and Android Enterprise enrollment methods

  • The user will get the enrollment email with a QR code, enrollment link in the following format.
  • Android Enterprise MDM enrollment email with QR code and token for secure device onboarding

  • Click on the sync devices button. The list of enrolled devices will appear in the same tab, as shown below.
  • Synced list of enrolled Android devices in Android MDM dashboard for Android Enterprise management

Step 7: Enroll the Mobile Device

  • On your mobile device, open any QR code scanner app and scan the QR code. After scanning, tap the link that appears to proceed. (If the QR code does not work, use the “Enrollment link” provided in the email.)
  • Scan Android Enterprise MDM enrollment QR code and open Google setup on Android phone

  • You will see the screen below. Click Next to continue.
  • Android Work Profile setup screen during Android Enterprise MDM enrollment with Next step

  • Click on Agree.
  • Agree to Android Enterprise MDM enrollment terms on device during Work Profile setup

  • Click on Accept and continue after scanning the QR code.
  • Accept and continue to finish Android Enterprise MDM enrollment after QR code scan

  • Once accepted, a work profile will be created on your device, and your work apps will begin installing within the work profile. This process may take a few minutes.
  • Android Work Profile data setup progress during Android Enterprise MDM enrollment on mobile device

  • You will now see a separate work container on your device for your work apps and data.
  • Separate work and personal profiles on Android after successful Android Enterprise MDM enrollment

  • Your Android device has been successfully configured with the MDM solution.

Note: If you are getting the “Can’t Add Work Profile” issue, please follow the steps in this FAQ to resolve the problem or you can also reach out to us at uemsupport@xecurify.com for quick assistance.


External References


miniOrange unified endpoint management offers a wide variety of security features with flexible scalability, all available at the most affordable price to all types of businesses. Start by signing up now!


Want To Schedule A Demo?

Request a Demo